News: 1600153325

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Family wrongly accused of uploading pedo material to Facebook – due to US-EU date confusion in IP address log

(2020/09/15)


A family in Spain was erroneously accused of uploading child sex abuse material to Facebook because Spanish investigators read a date in a US report as if it used the European date format.

According to [1]a report in El Pais this month, Spanish authorities received a report from the US-based National Center for Missing and Exploited Children (NCMEC) that a specific IP address managed by Telefónica had uploaded child abuse material to Facebook on 10/11/2016.

In the US, that's October 11th, 2016 (MM-DD-YYYY), with some exceptions, but in Spain and other European countries, it's November 10th, 2016 (DD-MM-YYYY). Since 1988, the International Standards Organization has called for using the YYYY-MM-DD format ( [2]ISO 8601 ).

Because internet service providers often assign public IP addresses dynamically, different people end up using the same numeric internet address on different days or after reconnecting to their ISP. The family in question had been using the identified IP address, just not on the day the illegal material was uploaded to Facebook.

As recounted by El Pais reporter Jose Antonio Hernández, the family's home was searched on November 23, 2017, resulting in considerable disruption and distress. Police scoured mobile devices and took away a computer that the family eventually recovered through the help of an attorney.

The investigation remained open until February 8, 2018. According to Hernández, a subsequent report from Spain's General Council of the Judiciary acknowledges that the case against the family was brought in error and that the family should be compensated.

The family is said to have launched legal proceedings against Spanish authorities and is seeking €27,000 in damages. NCMEC and Spanish Justice Ministry did not immediately respond to requests for comment.

Data confusion issues are a relatively regular occurrence. Recently, geneticists [3]issued new guidelines on naming genome sequences because of Excel's tendency to convert certain gene designations into dates. In Canada, legislators [4]have tried unsuccessfully to pass [5]a law to mandate the use of the YYYY-MM-DD format because there isn't a government standard. And Europe's [6]tobacco tracing efforts are sometimes derailed by date format errors. ®

Get our [7]Tech Resources



[1] https://english.elpais.com/spanish_news/2020-09-08/the-spanish-family-wrongly-accused-of-child-pornography-due-to-a-mistake-reading-a-date.html

[2] https://www.iso.org/iso-8601-date-and-time-format.html

[3] https://www.theregister.com/2020/08/06/excel_gene_names/

[4] https://www.cbc.ca/news/canada/proposed-legislation-aims-to-settle-date-debate-1.3407640

[5] https://openparliament.ca/bills/42-1/C-208/

[6] https://ec.europa.eu/health/sites/health/files/tobacco/docs/tt_common_reporting_mistakes_en.pdf

[7] https://whitepapers.theregister.com/

International Standards Organization

Phil O'Sophical

Nitpick, it's the International Organization for Standardization. Known in French as the Organisation internationale de normalisation, and intentionally referred to as ISO, which matches neither, because to call it IOS or OIN would be to give one language precedence over the other and probably upset the French.

And yes, it would be good if companies used standards for things like dates and phone numbers. In my experience, European businesses tend to use the standards, and US ones tend to assume everything is American (or perhaps, to be unaware that anything non-American exists). When emailing my US colleagues I always write dates out with the month by name.

Re: International Standards Organization

Rameses Niblick the Third Kerplunk Kerplunk Whoops Where's My Thribble?

Given as we can't even agree on a standard spelling of Standardisation, what chance do they really have?

Though that one is easier to fix

Anonymous Coward

As the use of 'z' is correct in the UK and the US, even if the UK does tend to use 's' (which is never correct in the US).

Re: Though that one is easier to fix

Mage

Grey and Gray are both allowed in UK & Ireland. Only one is allowed in USA?

Re: Though that one is easier to fix

jake

Grey and gray are both used here in the US, depending on context and location.

Re: Though that one is easier to fix

Symon

Grey's Anatomy --> TV programme.

Gray's Anatomy --> Book.

Re: Though that one is easier to fix

dogcatcher

Bet there's a problem at US border control especially after a transatlantic flight when everyone looks grey.

Re: International Standards Organization

MrBanana

The common workaround for "internationali{z|s}ation" is i18n.

Re: International Standards Organization

Mage

Just kill the stupid US date format.

I don't mind them keeping inches, Fahrenheit, the confusing pounds alone for body weight or their spelling. Or their own names for things.

Though I try to either write the month or use YYYY-MM-DD. I now use YYYY-MM-DD on all my spreadsheets etc.

Re: International Standards Organization

jake

"I don't mind them keeping inches, Fahrenheit, the confusing pounds alone for body weight or their spelling. Or their own names for things."

That is ever so magnanimous of you. Thank you for your permission. In return, I'll allow you to keep spelling things in the French manner, instead of in proper English like wot we do.

As for other bits & bobs ... How many stone do you weigh, exactly? And what are the dimensions of your favorite cricket pitch? How many miles between York and Leeds? Lovely thing, that metrical system, eh?

Re: International Standards Organization

Ben Tasker

Look, why don't the two of you compromise.

@jake - you can start by admitting there's a fucking H in the word 'erbs

We'll accept that you say Aloominum because that's what it was originally called, and we amended it to make it match other element names

Re: International Standards Organization

Sean o' bhaile na gleann

I once landed a gig with US-based company. The bit of paper I thankfully had in my hand specified a start date of "1st December yyyy". When I turned up at the office, HR tried to kick me out, saying I wasn't expected until 12 January, conveniently ignoring the change of year number...

Re: Pounds alone for bodyweight

I am the liquor

Never mind bodyweight, they use pounds alone for everything, no matter how ridiculous the numbers get. They will tell you with a straight face that the cargo capacity of a C5 is [1]281,001 lb or that the Statue Of Liberty stands on [2]54,000,000 lb of concrete.

[1] https://www.af.mil/About-Us/Fact-Sheets/Display/Article/104492/c-5-abc-galaxy-c-5m-super-galaxy/

[2] https://www.nps.gov/stli/learn/historyculture/statue-statistics.htm

Re: Pounds alone for bodyweight

Phil O'Sophical

the cargo capacity of a C5 is 281,001 lb

And absolutely not 281,002 lb?

What if the pilot had an especially big breakfast?

Re: Pounds alone for bodyweight

Craig 2

"What if the pilot had an especially big breakfast?"

Tower: Sorry, you're not cleared for takeoff until you & the copilot go for a shit.

re: Just kill the stupid US date format.

Anonymous Coward

Don't forget their insistence in using AM/PM in published timetables.

They really do need to get into the 20th Century let alone the 21st.

Re: re: Just kill the stupid US date format.

onemark03

Agree entirely.

And let's make sure we don't end up driving on the wrong (right-hand) side of the road, too! ;-)

Re: International Standards Organization

jake

"t would be good if companies used standards for things"

The nice thing about standards is that there are so many of them to choose from. —Andrew S. Tanenbaum

Simple solution

Steve Button

If we could just stop using a number for the date, and adopt 15-Sep-2020, or Sep-15-2020 for Americans, then we would all be happy(ier). At least these poor sods would have been happier.

Re: Simple solution

Steve Button

Even as I hit "Submit" I realised that this would not work, because of foreign languages. So, let's stick with the ISO standard for now, until English becomes the de facto standard language on the planet.

Re: Simple solution

JetSetJim

>until English becomes the de facto standard language on the planet.

Depending on politics, birth rates and the 4 horsemen, the de facto language may end up being Chinese, Russian, Arabic, Hindi or any number of others

The date stuff will be a clusterfuck until Excel has a tool to swap format without altering the digits in the string displayed. Am fed up from importing a spreadsheet with it set in USian into a UK spreadsheet and it borking the whole lot

Re: International Standards Organization

Anonymous Coward

I think US administration should introduce sanctions against them. And against all those rogue states that worship their terrible, undemocratic metric system threatening the American Way of Life!

Liberty at stake because of stupid mistakes

tip pc

Our liberty is at stake because those that should know better make stupid mistakes that are then reinforced by a system that decides to hide mistakes rather than self discover them before taking action to disrupt peoples freedoms.

I'd like to see all agencies, companies etc, government public or private, annually disclose all data that they processed on people to those people.

I'm sure we all would be surprised and alarmed at the amount of data collected on us & the reasons for processing that data and will all want stronger controls.

Its this work going on in the background behind our backs that is the most dangerous as we individually have no oversight or ability to correct mistakes, often no ability ever to correct mistakes.

Another reason an IP

steviebuk

Address shouldn't be used as evidence. Like the old story of a IP being on a list of movie or music pirates. That IP address turned out to be a printer.

And with the ability to break into anyone's home wifi, you could easily set anyone up. "It came from their IP address, so must be someone in that property and couldn't possibly be the person sat outside in their car with a big aerial on the roof"

Re: Another reason an IP

LDS

Yes, time to switch to IPv6 and fixed prefixes and addresses for everybody, so good-bye to "plausible deniability" for movie and music pirates... like it or not, IP addresses are and will be used - of course as long as they change who had which IP must be carefully checked.

Anyway in most contracts - at least here - the users accept full responsibility for what their networks are used for - and it was the same before with telephone lines too. If you have lame security you may not be able to use it as an excuse for illegal uses of your connection.

To get the VoIP credentials for my line to use my own devices instead of the ISP-supplied router, I had to specifically sign and accept responsibility for any illegal access to my line.

Re: Anyway in most contracts - at least here - the users accept full responsibility

Jimmy2Cows

I call that an unenforcable contract clause.

Given that many domestic routers are controlled by the ISP not the service user(s), and the frequent discovery of router security holes, as well as the ability to discover, connect to and compromise a router from outside a service user's property, there's no way a user could provably be liable for what happens at their router.

Re: Anyway in most contracts - at least here - the users accept full responsibility

LDS

It's already been enforced, don't worry. You'll need to prove you've been hacked - the fact a device could be hacked is not enough. If your car kills someone, you'll need to prove it was stolen, otherwise you're in trouble. The fact a car can be stolen, and cars are routinely stolen, is not enough.

It's like the excuses of people posting something very wrong on Twitter and then claiming their account was hacked.

Internet is not a place where you can do anything without any risk to be identified and persecuted....

Re: Anyway in most contracts - at least here - the users accept full responsibility

Jimmy2Cows

Just because it has been enforced doesn't make it right.

And in your example the prosecution has to prove it was me driving my car, and not someone else. Burden of proof is on the prosectution, not the defendant. At least in this decreasingly civilised part of the world. For now.

Yes, the cops will give me a hard time and I'll have to provide a strong alibi or evidence that I wasn't involved, but it's still on the prosecution to prove I was driving.

But all this is deviating from the point that an IP address alone should never be considered reliable evidence of someone's involvement or culpability.

Re: Anyway in most contracts - at least here - the users accept full responsibility

LDS

As the owner of the car you're in most legislation responsible for what the car is used - and it's up to the owner to demonstrate the car was used by someone else. "Ownership" usually implies responsibilities as well.

The burden of proof is on the prosecution, but laws also assign specific and implied responsibilities in many situations - and it's up to the defendant to demonstrate someone else was actually responsible. Think about someone who sign a balance - if it is found false, you're responsible unless you can prove someone deceived you and gave you false numbers.

Re: Another reason an IP

Doctor Syntax

"If you have lame security you may not be able to use it as an excuse for illegal uses of your connection."

It depends on who "you" refers to. If it's a business then there should be an expectation of reasonable care being taken to defend the network and factors such as size of business, number of data subjects and amount and sensitivity of data should determine what's reasonable. In the case of a private household it's more reasonable to look on the householder as victims in the case of an intruder.

None of that, of course, excuses sloppy investigation.

11Oct16

noisy_typist

Yes, this format will annoy non English speakers, but a large US firm I used to work for insisted on this format everywhere because it is unambiguous and still reads well. It is also still easy for a machine to read.

Re: 11Oct16

Gene Cash

> unambiguous

Not without at least a 4-digit year. So is that the 16th of October 2011? Or the 11th of October 2016??

Re: 11Oct16

Doctor Syntax

And that's assuming the century.

Re: 11Oct16

Anonymous Coward

Is that referring to 2016-10-11, 1916-10-11, 2011-10-16, or 1911-10-16 ???

Re: 11Oct16

Dave K

As well as the actual ambiguity mentioned above, it also has the flaw of not being sortable either numerically or alphabetically. The ISO standard of YYYY-MM-DD is the best one, and also means that it sorts numerically when applied to filenames.

Bring back VMS Standard Date/Time...

Anonymous Coward

Actually, DD-MON-YYYY (or YYYY-MON-DD if you want it reversed) is superior - it means that you can look at the date and be certain that the month and year you are looking at is indeed a month and a year.

Remember, you may know what your data means, but other people aren't you.

Yes, MON will be different in different countries. Localisation exists - this is not a new problem, and in this case the localisation will be obvious. With MM and DD it isn't always clear.

Dates are generally stored using a date/time variable, so sorting is only really an issue when you insist on storing your date as a string (or indeed, embedding it in a filename) - in that case yes you should use YYYYMMDD, but that should be an exception.

Re: Bring back VMS Standard Date/Time...

Doctor Syntax

Three letters: I S O

Re: Bring back VMS Standard Date/Time...

Steve Davies 3

one of the key figures behind the standardisation of Character sets worked for Digital and on the I18N committee.

His email address was (from memory) I18N@dec.com

That was a long time ago though.

Re: Bring back VMS Standard Date/Time...

Anonymous Coward

Thank you @Steve Davis 3 - I did not know that.

@Dr Syntax: Yelling I S O is missing the point. The ISO standard is great if absolutely everyone follows it. But not everyone does, and you cannot tell if an arbitary date is using it.

The rest of you: The whole point here is that MM and DD are being confused because unless you *know the date format being used* you cannot distinguish between them for the first 12 days of the month in any arbitrary date string. My point is that MON removes that ambiguity.

Re: 11Oct16

Anonymous Coward

and then you try to sort the column by date order and it all goes wrong as well.

Shows, despite the size of the company their thinking can still be stupid. In a large company you'd hope there'd be more people who'd say "hold on that doesn't work", but instead there's just more people who don't want to get involved.

Re: 11Oct16

DJO

I tend to use the style "11 Oct 2016" but only where I have written the sort routines so the dates sort correctly, otherwise always "2016 10 11"

Re: 11Oct16

Mike 125

>11Oct16

> it is unambiguous

No, that's biguous.

How is this so hard.

Re: 11Oct16

Doctor Syntax

"a large US firm I used to work for insisted on this format everywhere"

That's because they didn't know any better.

Re: 11Oct16

Dave559

«"a large US firm I used to work for insisted on this format everywhere"

That's because they didn't know any better.»

Well, they are a US company. They probably also assume that every one of their customers everywhere in the world has a "zip code" (with a specific format), that there is never any need to specify a country code for phone numbers, that said phone numbers absolutely must be able to be hammered into a nnn-nnn-nnnn format, and that producing product description sheets with measurements in squiggles and ozzes would mean anything to anyone else… (It's particularly disheartening to sometimes see that last for products from Chinese companies in their product illustrations on $well_known_international_shopping_sites, which probably means as little to them as it does to the majority of their worldwide customers.)

Re: 11Oct16

Andy Non

I once tried to register on a site that was intended for a world-wide audience (with a drop down box for country) but the registration process would not proceed until I entered a valid (US) zip code. Duh.

Re: 11Oct16

Already?

11Oct16 format would have been fine until the year 2001; before then 11Oct98 was totally unambiguous, and it will be in a dozen or so years time when 11Oct32 is also unambiguous, albeit subject to suspicions of typos. For the current span where day no and year no overlaps, it's not unambigiuous.

Re: 11Oct16

TimMaher

Y2K bug.

NISM?

Re: 11Oct16

Phil O'Sophical

unambiguous and still reads well. It is also still easy for a machine to read.

And as long as it doesn't need to sort it chronologically.

Different date formats are a liability and risk to life and health

Elledan

We have all seen the joys that converting between metric and Imperial system brings (even if the latter is defined in the former). Wherever such different notations touch and interact there is the potential for confusion, loss of property, injury and life.

In this case as well, it's probably good that nobody lost their life and things should get sorted out over time as presumably red-faced officials are forced into admitting the mistake. Yet it could have been so much worse.

Imagine a US-trained nurse, misinterpreting a date given on medical equipment or files in a Spanish or Korean hospital? Decades of learning to interpret date strings as MM/DD/YY(YY) when the rest of the world does not use that format is just begging for serious mistakes to be made. Like with medication or examination intervals.

Without further context provided, what dates would 01-02-03 or 01-02-2006 be? Former (sadly still common) format could be anything from the first of February, 2003 to the second of January, 2003, to the third of February, 2001. Latter could be the first of February, or the second of January.

Why do we accept such an obvious liability?

FFS

Hubert Cumberdale

The US date format really pisses me off. It makes no sense at all. ISO is probably onto a loser trying to get everyone to do it backwards (though that's how I name many files), but the US should at least use a date format that's internally consistent rather than middle-endian.

Pickle's Law:
If Congress must do a painful thing,
the thing must be done in an odd-number year.